RUMBO IA CRM — publisher policy delta for OpenAI review

Date: 2026-09-10 UTC Candidate SHA: 9152f5a50de42be55508f0effed5ed09aee44c60 Status: PREPARED_ONLY — NOT PROMOTED TO LIVE PUBLISHER SITE

Why this delta is required

OpenAI's remote MCP review requires public website, support, privacy, and terms URLs that match the publisher, and the privacy policy must cover user-related data the MCP processes or returns. Fresh external readback shows all four configured URLs return HTTP 200, but /openai-support still serves generic RUMBO IA marketing content and /openai-privacy describes only website/contact processing. Neither is sufficient evidence for the bounded MCP surface.

Required support-page semantics

The live /openai-support page should identify itself as RUMBO IA CRM Support and state, in substance:

  • It supports the RUMBO IA CRM plugin for OpenAI/ChatGPT.
  • Public v1 exposes exactly four bounded tools: service readiness, note proposal preparation, lead-stage-change proposal preparation, and outreach-draft request preparation.
  • Tool outputs are proposals or readiness metadata only; proposal outputs remain REVIEW_REQUIRED and side_effect=false.
  • The plugin does not expose customer-data search/retrieval, CRM writes, autonomous sends, production authority, or submission authority.
  • Users should not place passwords, API keys, access tokens, or unnecessary sensitive/customer data in tool inputs.
  • Support contact: sebastian@rumbo.verso.fans.
  • Link visibly to the OpenAI-specific privacy and terms pages.

Required privacy-page disclosure

The live /openai-privacy page should disclose the actual bounded MCP data flow. A suitable minimum disclosure is:

RUMBO IA CRM plugin privacy notice

RUMBO IA CRM provides a bounded MCP integration for OpenAI/ChatGPT. Public v1 does not search or retrieve customer records from a CRM and does not perform CRM mutations or send messages.

When a user asks the plugin to prepare a proposal, the MCP service may process the information the user supplies for that request. Depending on the selected tool, this can include workspace or subject/lead identifiers, note text, stage labels, an optional reason, a communication channel, and an outreach objective. The service returns that supplied information as part of a reviewable proposal or returns bounded service-readiness metadata.

The current public v1 does not intentionally persist those tool inputs to a CRM or application database, does not use them to autonomously contact third parties, and does not sell them. Users should avoid submitting passwords, API keys, access tokens, or personal/customer information that is not necessary for the requested proposal.

Requests are delivered through OpenAI/ChatGPT and the MCP hosting infrastructure. Hosting and network providers may process ordinary technical information such as IP address, browser/client metadata, request timing, and service logs for security and operation according to their own applicable terms and policies.

For privacy requests or questions about RUMBO IA CRM, contact sebastian@rumbo.verso.fans.

Terms status

Fresh readback of /openai-terms is HTTP 200 and identifies RUMBO IA, but the final publisher review should confirm that the selected verified publisher identity matches the name/contact/website used across the listing and policies.

Promotion gate

This document is a handoff artifact only. It does not authorize a production-site change, merge, publication, submission, or policy attestation.

POLICY_SOURCE_PREPARED != LIVE_POLICY_PROMOTED != VERIFIED_PUBLISHER != SUBMISSION_AUTHORITY